CVE-2019-10074
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been di
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good reason and never within a field that accepts user input.
Mitigation: Upgrade to 16.11.06 or manually apply the following commit on branch 16.11: r1858533.
CRITICAL · CVSS 9.8
EPSS 0.01128
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0